CVE-2006-2843: High severity REDAXO REDAXO vulnerability
PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDEPATH] parameter in (a) addons/importexport/pages/index.inc.php and (b) pages/community.inc.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2843?
CVE-2006-2843 has a moderate severity level due to its potential for arbitrary PHP code execution.
How do I fix CVE-2006-2843?
To fix CVE-2006-2843, it is recommended to upgrade Redaxo to a version that is not affected by this vulnerability.
What is the main impact of CVE-2006-2843?
The main impact of CVE-2006-2843 is that it allows remote attackers to execute arbitrary PHP code on the affected system.
Which versions of Redaxo are affected by CVE-2006-2843?
CVE-2006-2843 specifically affects Redaxo version 2.7.4.
What are the vulnerable components of Redaxo in CVE-2006-2843?
The vulnerable components in CVE-2006-2843 are the addons/import_export/pages/index.inc.php and pages/community.inc.php files.